Incident response, 7 days a weekPapeete · Fort-de-France · ParisFREN
TAVITA CYBERSECURITYCyber guardian of the territories
Home › Incident response

Under attack? We respond the same day.

Called in as soon as the facts are established, we stop the attack, secure the network and Microsoft 365 tenants, document the investigation and cooperate with the investigating authorities. We then strengthen your defences so it doesn't happen again.

The first few hours

What to do right away, even before we arrive

Download the quick-reflex memo (PDF)
1
Isolate without switching offUnplug the network cable or turn off Wi-Fi on suspicious machines. Don't switch them off: the memory holds evidence.
2
Note the time and take photosRansom screens, error messages, suspicious emails: photos, time of each observation, who saw what.
3
Raise the alarm internallyNotify management and whoever manages IT. Appoint a single point of contact going forward.
4
Change critical access credentialsFrom a clean device: administrator accounts, email, online banking. Turn on two-factor authentication.
5
Call the bank if a wire transfer is at stakeRequest the funds be recalled immediately; after a few hours, the money is gone.
6
Call us, or launch the 17Cyber diagnostic+33 6 99 63 17 11 · +689 87 30 41 25. Remote support from the moment you call. The “Online Cyber Assistance” button at the bottom of the page opens the official 17Cyber diagnostic (Cybermalveillance.gouv.fr). Don't pay, don't reinstall, don't handle it alone.
Downloadable factsheets

Our practical factsheets, to keep close at hand

Three free double-sided documents, ready to print or share with your teams.

Memo · to display

Cyberattack: the right reflexes to respond

Recognising an attack, the 6 actions to take in the first hour, what you must not do, who to call and what deadlines to meet (complaint, CNIL, insurer), followed by the reflexes for each type of attack.

Download the memo (PDF)
French Polynesia

Cyber incident response and crisis management

The threat landscape in the Pacific, the right reflexes while you wait for our call, and the details of our response: remote from the first call, on-site response in Tahiti, with our director travelling to you in the event of a critical incident.

Download the French Polynesia factsheet (PDF)
Martinique · Antilles

Cyber incident response and crisis management

The threat landscape in the Antilles, the right reflexes while you wait for our call, and the details of our response: remote from the first call, on-site in Martinique and Guadeloupe from Sainte-Marie.

Download the Martinique factsheet (PDF)
Our response process

Five phases, one point of contact

D+0ContainSupport from the first call, isolation of compromised access, halting the ongoing attack.
D+0 → D+2SecureNetwork, accounts, Microsoft 365 tenant, backups: the attacker's access is shut down.
D+1 → D+5InvestigateDiagnostic and report tracing the actions, findings and recommendations taken.
In parallelReport and cooperateComplaint filed within 72 hours, CNIL, insurer; cooperation with the national police (DTPN).
ThenStrengthenCorrective measures, hardening, staff awareness training to prevent recurrence.
Testimonials

They called on us in the middle of an attack, or to avoid one

The local authorities concerned are not named.

Incident response
Local authority — French PolynesiaFebruary 2024 incident · Tahiti

“Called in as soon as the facts came to light, TAVITA CYBERSECURITY responded very quickly to stop the attack. It secured our network, including our Microsoft 365 tenant, carried out an initial investigation and diagnostic recorded in a report, and worked closely with the national police's cybercrime investigation services.”

Chief Administrative Officer
Incident response
Municipality — MartiniqueAugust 2025 incident

“TAVITA CYBERSECURITY responded very quickly to stop the attack our municipality was facing. It carried out the intervention effectively, securing the network and then implementing the necessary corrective measures, and ran a cybersecurity awareness session for our staff.”

The Mayor
Security hardening
Municipality — French PolynesiaSupport and strengthening of IT security

“TAVITA CYBERSECURITY brought us its expertise in consulting, auditing, technical support and recommendations, with professionalism, availability and rigour. This support strengthened our infrastructure's security and improved our practices. We recommend TAVITA CYBERSECURITY for its expertise and thoroughness.”

The Mayor

After the crisis: not suffering the same attack twice

In the cases we handle, the attack almost always starts from a Microsoft 365 account without MFA with forwarding rules set up by the attacker, or from a stolen VPN access on an unpatched firewall. The “Strengthen” phase fixes these root causes:

  • MFA everywhere, review of access rights and mailbox rules
  • Immutable, offline, tested backups
  • Updating and hardening exposed equipment
  • Staff awareness and anti-fraud procedure for bank transfers
  • The "what if it happens" plan: who to call, what to unplug, how to restore, what to report

Preparing before the incident

A cyber crisis tabletop exercise with your management, a written and well-known DRP, and a follow-up contract with a direct line all cut your downtime significantly on the day it happens.